CVE-2024-40586

MEDIUM

FortiClient <7.4.0 - Privilege Escalation

Title source: llm
STIX 2.1

Description

An Improper Access Control vulnerability [CWE-284] in FortiClient Windows version 7.4.0, version 7.2.6 and below, version 7.0.13 and below may allow a local user to escalate his privileges via FortiSSLVPNd service pipe.

Exploits (1)

nomisec WORKING POC 1 stars
by Hagrid29 · poc
https://github.com/Hagrid29/CVE-2024-40586-Windows-Coerced-Authentication-in-FortiClient

Scores

CVSS v3 6.7
EPSS 0.0002
EPSS Percentile 4.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-284
Status published
Products (2)
fortinet/forticlient 7.4.0
fortinet/forticlient 7.0.3 - 7.0.14
Published Feb 11, 2025
Tracked Since Feb 18, 2026